← Back
CWE-640

317 CVEs • Abstraction: Base • Likelihood of Exploit: High

Weak Password Recovery Mechanism for Forgotten Password

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

JSON object

Loading...

CVEs (317)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
1Enterprise Virtualization
Nov 21, 2024
Jul 27, 2018
N/A· v4
6.3 MEDIUM· v3
2.1 LOW· v2
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the...Show more
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining access to those accounts.Show less
1Gitlab
1Gitlab
Nov 21, 2024
Jul 3, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's...Show more
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromised.Show less
1Trovebox
1Trovebox
Nov 21, 2024
Jun 26, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Trovebox version <= 4.0.0-rc6 contains a Unsafe password reset token generation vulnerability in user component that can result in Password reset. This attack appear to be exploitable via HTTP request. This vulnerability...Show more
Trovebox version <= 4.0.0-rc6 contains a Unsafe password reset token generation vulnerability in user component that can result in Password reset. This attack appear to be exploitable via HTTP request. This vulnerability appears to have been fixed in after commit 742b8ed.Show less
1Instant Update
1Instant Update Cms
Nov 21, 2024
Jun 26, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Instant Update CMS contains a Password Reset Vulnerability vulnerability in /iu-application/controllers/administration/auth.php that can result in Account Tackover. This attack appear to be exploitable via network connec...Show more
Instant Update CMS contains a Password Reset Vulnerability vulnerability in /iu-application/controllers/administration/auth.php that can result in Account Tackover. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in v0.3.3.Show less
1Ltb Project
1Ldap Tool Box Self Service Password
Nov 21, 2024
Jun 14, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data...Show more
LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data type is not constrained to be a string.Show less
1Synology
1Diskstation Manager
Jun 17, 2026
Jun 8, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Unverified password change vulnerability in Change Password in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to reset password without verification.
1Quest
1Kace System Management Appliance
Nov 21, 2024
May 31, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue managed that runs with root privileges and only allows a set of commands. One of t...Show more
In order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue managed that runs with root privileges and only allows a set of commands. One of the available commands allows changing any user's password (including root). A low-privilege user could abuse this feature by changing the password of the 'kace_support' account, which comes disabled by default but has full sudo privileges.Show less
1Vaultize
1Enterprise File Sharing
May 30, 2025
Apr 25, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. Enumeration of users is possible through the password-reset feature.
1Cmsmadesimple
1Cms Made Simple
Nov 21, 2024
Apr 13, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
CMS Made Simple (CMSMS) through 2.2.6 contains an admin password reset vulnerability because data values are improperly compared, as demonstrated by a hash beginning with the "0e" substring.
1Wordpress
1Wordpress
Nov 21, 2024
Apr 12, 2018
N/A· v4
8.1 HIGH· v3
5.0 MEDIUM· v2
WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.
1Microsoft
1Asp.net Core
Nov 21, 2024
Mar 14, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how web applications that are created from templates validate web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability".
1Keycloak
1Keycloak
Nov 21, 2024
Feb 21, 2018
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request. An attacker could use this flaw to craft a malicious password reset request...Show more
It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request. An attacker could use this flaw to craft a malicious password reset request and gain a valid reset token, leading to information disclosure or further attacks.Show less
1Cisecurity
1Cis Cat Pro Dashboard
Nov 21, 2024
Jan 31, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administrative user's e-mail address and send a forgot password email to themselves, thereby gaining administ...Show more
In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administrative user's e-mail address and send a forgot password email to themselves, thereby gaining administrative access.Show less
1Mahara
1Mahara
Nov 21, 2024
Jan 30, 2018
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
An issue was discovered in Mahara before 18.10.0. It mishandled user requests that could discontinue a user's ability to maintain their own account (changing username, changing primary email address, deleting account). T...Show more
An issue was discovered in Mahara before 18.10.0. It mishandled user requests that could discontinue a user's ability to maintain their own account (changing username, changing primary email address, deleting account). The correct behavior was to either prompt them for their password and/or send a warning to their primary email address.Show less
1Gps Server
1Gps Tracking Software
Nov 21, 2024
Jan 2, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to t...Show more
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier for remote attackers to obtain access by predicting this new password. This is related to the use of gmdate for password creation in fn_connect.php.Show less
2Cloudfoundry
Pivotal Software
3Cf Release
Cloud Foundry Elastic RuntimeCloud Foundry Uaa
May 13, 2026
Oct 24, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links.
1Prominent
1Multiflex M10a Controller Firmware
May 13, 2026
Oct 17, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When setting a new password for a user, the application does not require the user to know the original password. An...Show more
An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When setting a new password for a user, the application does not require the user to know the original password. An attacker who is authenticated could change a user's password, enabling future access and possible configuration changes.Show less
1Ellucian
1Banner Student
May 13, 2026
Sep 11, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via unspecified vectors, aka "Weak Password Reset."
1Zte
1Zxv10 W300 Firmware
May 13, 2026
Aug 24, 2017
N/A· v4
7.5 HIGH· v3
8.5 HIGH· v2
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changi...Show more
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changing the username parameter from "support" to "admin".Show less
1Fedoraproject
1389 Directory Server
May 13, 2026
Aug 16, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.